This policy explains how we collect and use your personal data when you visit www.moveitmalta.com, buy tickets, sign up for our announcements or contact us.
Who we are
The data controller is Puerto Malta Limited (trading as Move it! Malta), registration number C 94921, registered office 1, Rita Ville, Triq il-Hemel, Swieqi SWQ 3050, Malta, VAT MT27275815.
Contact for anything related to your data: info@moveitmalta.com or WhatsApp +356 9956 1033.
What data we collect
- Ticket purchases: name, email address, phone/WhatsApp number (optional), the tickets and dates you buy, amounts, order number and the time your ticket is scanned at the entrance. Card payments are processed by Stripe: we never see or store your full card details.
- Announcement emails: your email address, language, where you signed up and the date and time of your consent.
- Messages: what you send us by WhatsApp, email or social media.
- Website use: pages visited, the website or campaign you came from, approximate country (derived from your IP address, which we do not store), device type, language and page speed. Without your consent this is measured without cookies; with your consent we also use a random identifier to recognise returning visits (see the Cookie policy).
- Partner referrals: if you arrive from a partner website, the partner's code, so the sale can be attributed to it.
- Advertising and analytics tools: if you accept them, Google (Analytics, Ads) and Meta (Facebook/Instagram) collect data about your visit through cookies, under their own policies.
Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Selling and delivering your tickets, checking them at the entrance, customer service about your booking | Performance of a contract |
| Invoices, accounting and tax records | Legal obligation |
| Emailing you when new dates are announced | Your consent (you can unsubscribe at any time) |
| Statistics with cookies, Google Analytics, advertising measurement and remarketing | Your consent through the cookie banner |
| Cookieless, aggregated statistics; security; preventing fraud and abuse | Our legitimate interest in running and protecting the website |
| Attributing sales to partner websites | Our legitimate interest and our agreements with those partners |
Who we share it with
We only share the data needed with providers that work on our behalf, under data processing agreements:
- Stripe (card payments and fraud prevention)
- Vercel (website hosting)
- Supabase (database)
- Resend (sending emails)
- ImprovMX and Brevo (email we receive at and send from our addresses)
- Xero (invoicing and accounting)
- Google and Meta (analytics and advertising, only with your consent; Google Maps if you choose to show the map)
- Partner sales channels that sold you the ticket, for the bookings made through them
We may also disclose data to authorities when the law requires it. We do not sell your personal data.
International transfers
Some of these providers are based outside the European Economic Area (mainly the United States). Transfers are covered by the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.
How long we keep it
- Orders, tickets and invoices: for as long as Maltese accounting and tax law requires.
- Announcement list: until you unsubscribe.
- Detailed website statistics: up to 13 months.
- Messages: as long as needed to handle your request.
- Cookies: see the durations in the Cookie policy.
Your rights
You can ask to access, correct or delete your data, to restrict or object to its use, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time: use the unsubscribe link in our emails, or "Cookie settings" at the bottom of every page.
Write to info@moveitmalta.com. If you are not satisfied with our answer, you can complain to the Information and Data Protection Commissioner (IDPC) of Malta (idpc.org.mt) or to the data protection authority of your country.
Age
Move it! Malta is an event for people aged 17 and over, and this website is aimed at them.
Security
We protect your data with encrypted connections (HTTPS), access restricted to authorised staff and providers that apply appropriate security measures.
Changes
We may update this policy. The date at the top shows the latest version; if the changes are important, we will tell you on the website or by email.